PatchSiren

leadrebel CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM leadrebel CVE published 2026-04-08

CVE-2026-39664

A Missing Authorization vulnerability in leadrebel Leadrebel (from n/a through <= 1.0.2) allows Exploiting Incorrectly Configured Access Control Security Levels, with a CVSS score of 5.3 and MEDIUM severity. This issue arises from a lack of proper authorization checks, potentially allowing unauthorized access or actions within the Leadrebel plugin. Users of affected versions should review and apply patche [truncated]